Support Forums

Poor admin security settings for user groups?

This is a discussion on Poor admin security settings for user groups? within the Technical Support forums, part of the Technical Support Forums category; Hiya, I have created a 2nd admin user account with reduced access settings using the "Administration Capabilities" section. Logging in ...


Go Back   68 Classifieds Forums > Technical Support Forums > Technical Support

This topic is resolved.

If you have a similar issue that this thread does not address, open a new related support topic.

 
Thread Tools Display Modes
Old 02-04-2009, 09:34 AM   #1
Junior Member
 
Freddy's Avatar
 
Join Date: Feb 2009
Posts: 16
Rep Power: 13
Freddy is on a distinguished road
Default ANSWERED - Poor admin security settings for user groups?

Hiya,

I have created a 2nd admin user account with reduced access settings using the "Administration Capabilities" section.

Logging in with this account you can go into edit user and bump yourself up to all areas and worse still you can remove access for the main admin account. I assume you can also delete it (I don't want to test this).

I must be doing something wrong?

I need reduced admin levels so that others can login and do some editing (including user settings) but not bump themselves or remove me!

I tried creating a new user group called 'mod' but the "Administration Capabilities" select isn't present for any group other than admin.

Plus when I drop the test user account from admin to 'mod' level and try to login with that account it says the user isn't registered when I try a password recovery.

Many thanks

Last edited by Freddy; 02-04-2009 at 11:37 AM.
Freddy is offline  
Old 02-04-2009, 10:36 AM   #2
curmudgeon
 
Join Date: Mar 2006
Posts: 5,416
Rep Power: 139
Lhotch is a glorious beacon of light Lhotch is a glorious beacon of light Lhotch is a glorious beacon of light
Default

Freddy,

We need to know what version of the script you are using.
__________________
Larry

Knowledge learned is more valuable than knowledge given.
Lhotch is offline  
Old 02-04-2009, 10:47 AM   #3
Junior Member
 
Freddy's Avatar
 
Join Date: Feb 2009
Posts: 16
Rep Power: 13
Freddy is on a distinguished road
Default

Apologises Larry.

v4.1.0 RC3 Designer

Thanks,
Fred
Freddy is offline  
Old 02-04-2009, 10:51 AM   #4
curmudgeon
 
Join Date: Mar 2006
Posts: 5,416
Rep Power: 139
Lhotch is a glorious beacon of light Lhotch is a glorious beacon of light Lhotch is a glorious beacon of light
Default

Quote:
Originally Posted by Freddy View Post
Apologises Larry.

v4.1.0 RC3 Designer

Thanks,
Fred
Thats actually a BETA product and not even the most current one. What I recommend in situations like this is that you upgrade to the latest release candidate and if you still notice this problem click on the support link menu above the forum and chose "bug tracker". Then fill in the displayed form to get the issues reported to the developers so it can be looked into.
__________________
Larry

Knowledge learned is more valuable than knowledge given.
Lhotch is offline  
Old 02-04-2009, 10:58 AM   #5
Junior Member
 
Freddy's Avatar
 
Join Date: Feb 2009
Posts: 16
Rep Power: 13
Freddy is on a distinguished road
Default

Ah I see. Only purchased a few days ago.

Before I reported as a bug I wanted to see if I was doing something wrong

Didn't realise it was beta. I will install the latest non beta and try again.

Many thanks,
Fred
Freddy is offline  
Old 02-04-2009, 11:21 AM   #6
68 Classifieds Staff
 
Eric Barnes's Avatar
 
Join Date: Mar 2006
Location: Belmont, NC
Posts: 5,489
Rep Power: 136
Eric Barnes is just really nice Eric Barnes is just really nice
Default

Actually that is the way it was designed. The admin capabilities restricts access to certain pages in admin. It doesn't have a check to prevent them from editing their own capabilities if they have access to edit users.

That is a good idea though and I think that could be a very useful setting.
__________________
Eric Barnes
68 Classifieds Developer
Customer Area | Issue Tracker | Documentation | 68C Mods | 68 @ Twitter | My Modules
Eric Barnes is offline  
Old 02-04-2009, 11:30 AM   #7
Junior Member
 
Freddy's Avatar
 
Join Date: Feb 2009
Posts: 16
Rep Power: 13
Freddy is on a distinguished road
Default

Quote:
Originally Posted by Eric Barnes View Post
Actually that is the way it was designed. The admin capabilities restricts access to certain pages in admin. It doesn't have a check to prevent them from editing their own capabilities if they have access to edit users.

That is a good idea though and I think that could be a very useful setting.
Thanks Eric for reply.

Surprised I'm the first to bring this up in all honesty. Fairly standard requirement for delegating back end tasks with minimal access.

That said I am loving the script

Fast support too!

Cheers,
Fred
Freddy is offline  
Old 02-04-2009, 11:32 AM   #8
68 Classifieds Staff
 
Eric Barnes's Avatar
 
Join Date: Mar 2006
Location: Belmont, NC
Posts: 5,489
Rep Power: 136
Eric Barnes is just really nice Eric Barnes is just really nice
Default

Thanks Fred. You know you are the first to mention this and it makes perfect sense. I would think just adding another checkbox will suffice in that section.
__________________
Eric Barnes
68 Classifieds Developer
Customer Area | Issue Tracker | Documentation | 68C Mods | 68 @ Twitter | My Modules
Eric Barnes is offline  
Old 02-04-2009, 11:34 AM   #9
68 Classifieds Staff
 
Eric Barnes's Avatar
 
Join Date: Mar 2006
Location: Belmont, NC
Posts: 5,489
Rep Power: 136
Eric Barnes is just really nice Eric Barnes is just really nice
Default

Just added this to the tracker: http://www.68classifieds.com/forums/issue-258/
__________________
Eric Barnes
68 Classifieds Developer
Customer Area | Issue Tracker | Documentation | 68C Mods | 68 @ Twitter | My Modules
Eric Barnes is offline  
Old 02-04-2009, 11:36 AM   #10
Junior Member
 
Freddy's Avatar
 
Join Date: Feb 2009
Posts: 16
Rep Power: 13
Freddy is on a distinguished road
Default

Quote:
Originally Posted by Eric Barnes View Post
Just added this to the tracker: http://www.68classifieds.com/forums/issue-258/
Thank you Sir.
Freddy is offline  
Closed Thread

Thread Tools
Display Modes


Similar Threads
Thread Thread Starter Forum Replies Last Post
User Groups island1 Templates, HTML, CSS, and Design Help 2 01-15-2009 03:54 PM
Do listing settings apply to admin? domino Technical Support 2 09-13-2008 07:11 PM
seller stores & user groups spaceboy Technical Support 0 04-22-2007 02:31 PM


All times are GMT -4. The time now is 03:44 AM.


Powered by vBulletin® Version 3.8.1
Copyright ©2000 - 2012, Jelsoft Enterprises Ltd.
Search Engine Friendly URLs by vBSEO 3.2.0